skip to main contentskip to footer

Quick links

  • Athletics
  • Make a gift
  • Newsroom
  • Job openings
  • Employee directory
  • Apply
  • Costs
  • Explore
Explore U of I
  • Visit and virtual tour
  • Student life
  • Find your degree
  • Get around campus
  • Meet Moscow
  • Join our email list
  • Events
  • Join ZeeMee
  • Athletics
Academics
  • Academic calendar
  • Find a major
  • Student support resources
  • Undergrad research opportunities
  • Meet the colleges
  • Online learning
  • Explore in-demand careers
Admissions
  • Meet your counselor
  • Deadlines
  • First-year students
  • Graduate students
  • Law students
  • Online students
  • Transfer students
  • International students
  • Admitted students
Financial aid
  • Cost of attendance
  • Steps for financial aid
  • FAFSA information
  • Financial aid FAQs
  • In-state scholarships
  • Out-of-state and international scholarships
  • Connect with financial aid
More
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives
Find your passion - Explore majors Become a Vandal - Start an application
  • U of I news
  • Make a gift
  • Athletics
  • Directory
Events
Residence Hall Move-in
Welcome home! Move into your residence hall and start settling in for the 2025–26 academic year.
New Student Orientation
Orientation helps you navigate campus life, connect with your peers and prepare for your first semester at U of I.
Week of Welcome
Aug. 19-24, 2025 | Celebrate the start of a new academic year with a full week of fun, informative and community-building events for all Vandals.
Events
News
Student Dan Lauritzen working in the drone lab with Jason Karl for the College of Natural Resources
Drone lab supports aerial-based research
University of Idaho Fall 2023 Start up events.
Five reasons to join a U of I club or organization
News
Support a Vandal - Make a gift
  • Apply
  • Costs
  • Explore
  • Explore
  • Academics
  • Admissions
  • Financial Aid
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives

Physical protection 

  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  1. Home/
  2. leadership/
  3. Information technology/
  4. IT standards/
  5. Physical protection

Overview

This updated standard is to help align existing practices within Office of Information Technology (OIT) around Physical Protection controls to the requirements in NIST 800-171 (PE | 3.10.x) as well as industry best practices. This document does not give full coverage of 3.10.x controls within 171 due to existing limitations and other requirements that are specific to CUI.

What is in this document:

  • Visitor monitoring requirements
  • Required content of physical logs
  • Standards for physical access devices
  • Remote work requirements

What is NOT in this document:

  • Log locations for physical logs
  • VandalCard or key security standards 
     

Policy Reference

  • APM 30.11 University Data Classification and Standards
  • APM 30.14 Cyber Incident Reporting and Response
  • APM 40.28 Access Control Policy
  • APM 95.13 Security Cameras

Purpose
This Physical Protection  standard supports APM 30.11 University Data Classification and Standards and other relevant university policies.

Scope
These standards are the minimum baseline for all managed and unmanaged systems that access, store or process University of Idaho data (see APM 30.14 C-6) or using University of Idaho technology resources (see APM 30.12 C-1) at the Low, Moderate- or High risk levels (see APM 30.11) not otherwise covered by an approved systems security plan.

This specifically includes university-operated data centers but may include other spaces where relevant data may be unencrypted.

Standards

U of I Office of Information Technology (OIT) is responsible for the content and management of these standards.

To request an exception to this standard contact: oit-security@uidaho.edu 

1. Escort visitors

Escort and monitor visitor activity in restricted areas.

  1. Visitors are escorted in restricted areas.
  2. Visitor logs must be included in the physical access log described below.
    1. These logs must also include the individual escorting the visitor.
2. Physical access logs

Maintain audit logs of physical access to areas in scope.

  1. Access to restricted areas must be recorded either electronically or via a sign-in sheet.
    1. Sign-in sheets must be appropriately secured from tampering as determined by OIT Security.
  2. Audit logs of physical access are maintained for at least three (3) years.
  3. Physical access logs should contain:
    1. The local time that access was provided.
    2. Each individual that access was provided to.
    3. The restricted area being accessed.
    4. The local time each individual exits.
3. Manage physical access devices

Control and manage physical access devices (key cards/readers, pin pads on locks, traditional keys, etc).

  1. Physical access devices are recorded with current access device holders / owner as per APM 40.28.
    1. Physical locks are assumed to be maintained by University of Idaho Facilities Management unless otherwise approved.
  2. Physical access devices are rotated/deauthorized/revoked when:
    1. Any access device is missing, lost, stolen or otherwise unaccounted for.
    2. Current access device holders are no longer in the role requiring access.
    3. Any unauthorized copy of access device is created.
  3. Permanent Physical access devices are assigned to individuals only while required to perform their role.
4. Alternative work site

To ensure that work can be done securely from remote locations the following standards must be met:

  1. While working at alternate work sites, individuals must:
    1. Connect through an approved remote access method such as vpn.uidaho.edu.
    2. Be in a private location or otherwise obscure their screen from others.
    3. Be using OIT-managed technology.
    4. Be in a private space or must take appropriate precautions against eavesdropping while taking phone/video calls discussing high-risk or regulated data.
  2. Alternate work sites that are used when accessing regulated data must adhere to any additional requirements of the regulation.
5. Verified locations

OIT Security will publish and maintain an internal document identifying areas that are approved for handling high-risk data.

  1. Handling of high-risk or other regulated data should not occur outside of these locations.
  2. These locations must meet the following requirements:
    1. Must control access points into the secure area using a VandalCard and pin or other method approved by OIT Security.
    2. Must have appropriate signage per regulation or contract such as PCI or CUI.
    3. Must be physically separated from unsecured areas.
    4. Must have cameras monitoring access points.

Other references

  1. NIST SP800-171r2 (February 2020)
  2. NIST SP800-53r5 (September 2020)
  3. NIST SP800-114r1 (July 2016)
  4. NIST SP800-46r2 (July 2016)
  5. CMMC glossary (December 2021)

Definitions

  1. Visitor

    Individuals without permanent physical access authorization credentials (I.E. VandalCard, key, door pin, etc.)

  2. Physical access device

    A device used for gaining physical access to an area such as key cards/readers, pin pads on locks, traditional keys, etc.

  3. Physical access device holder/owner

    The individual person currently in possession of, or responsible for a physical access device.

  4. Alternate work site

    Areas where work is approved to occur other than their university-controlled office space. This includes but is not limited to, public spaces on campus, home offices covered by flexplace agreement under FSH 3250 or supervisor-approved area.

  5. Federal Contract Information (FCI)

    “Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.” (CMMC Glossary)

    1. While encrypted, data is not considered FCI
  6. Controlled Unclassified Information (CUI)

    “Information that law, regulation or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.” (NIST SP 800-171)

    1. While encrypted, data is not considered CUI
  7. Restricted area

    A location used for storing, transmitting, processing, discussing or otherwise handling high-risk data or data with relevant regulations such as FCI/CUI.

Revision history

3/1/2024 — Minor updates

  • Minor formatting/wording/reference changes.

6/23/2023 — Original standard

  • Full re-write to align with NIST 800-171r2

Footer

Ready to apply?

Start your application
Joe Vandal head illustration

Footer Navigation

Resources

  • Policies
  • Privacy statement
  • Web accessibility
  • Title IX

Campus

  • Directory
  • Map
  • Safety
  • Events

Information For

  • Prospective students
  • Current students
  • Parents
  • Employees
Logo

University of Idaho

875 Perimeter Drive, Moscow, ID 83844

208-885-6111

info@uidaho.edu

Engage with U of I on Facebook. Get the latest U of I updates on X. Catch up with U of I on Instagram. Grow your professional network by connecting with U of I on LinkedIn. Interact with University of Idaho's video content on YouTube. Join the University of Idaho ZeeMee conversation.
Support a Vandal - Make a gift
  • Athletics
  • Jobs
  • News

© 2025 University of Idaho